Lucene search

K
oraclelinuxOracleLinuxELSA-2024-0121
HistoryJan 11, 2024 - 12:00 a.m.

container-tools:4.0 security update

2024-01-1100:00:00
linux.oracle.com
15
buildah
cockpit-podman
conmon
containernetworking-plugins
containers-common
container-selinux
criu
crun
fuse-overlayfs
libslirp
oci-seccomp-bpf-hook
podman
python-podman
runc
skopeo
slirp4netns
udica
security
update
cve
jira

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

62.5%

buildah
[1:1.24.6-7]

  • rebuild for CVE-2023-29406
  • Related: #2176055
    cockpit-podman
    [46-1]
  • update to https://github.com/cockpit-project/cockpit-podman/releases/tag/46
  • Related: #2061390
    conmon
    [2:2.1.4-2]
  • update to https://github.com/containers/conmon/releases/tag/v2.1.4
  • Related: #2176055
    containernetworking-plugins
    [1:1.1.1-6]
  • Rebuild with golang 1.20.6 or higher
  • Related: Jira:RHEL-4507
  • Related: Jira:RHEL-7442
    containers-common
    [1-38.0.1]
  • Updated removed references [Orabug: 33473101] (Alex Burmashev)
  • Adjust registries.conf (Nikita Gerasimov)
  • remove references to RedHat registry (Nikita Gerasimov)
    container-selinux
    [2:2.205.0-3]
  • fix build for stable module
  • Related: #2176055
    criu
    [3.15-3]
  • add Requires: criu-libs = %{version}-%{release} in criu-devel
  • add gating tests
  • Related: #1934415
    crun
    fuse-overlayfs
    [1.9-2]
  • update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.9
  • Related: #2176055
    libslirp
    oci-seccomp-bpf-hook
    [1.2.5-2]
  • fix compatibility with the new bcc
  • Related: #2176055
    podman
    [2:4.0.2-25]
  • rebuild with golang 1.20.6+ for CVE-2023-39321 CVE-2023-29409
  • Related: Jira:RHEL-4508
  • Related: Jira:RHEL-7443
    python-podman
    [4.0.0-2]
  • bump to v4.0.0
  • Related: #2176055
    runc
    [1:1.1.5-2]
  • rebuild for following CVEs: CVE-2022-41724
  • Resolves: #2179971
    skopeo
    [2:1.6.2-9]
  • rebuild because of CVE-2023-29406
  • Resolves: #2236831
    slirp4netns
    [1.1.8-3]
  • fix gating - don’t use insecure functions - thanks to Marc-Andre Lureau
  • Related: #2176055
    udica
    [0.2.6-4]
  • sync with stream-container-tools-4.0-rhel-8.8.0
  • Related: #2176055

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.002

Percentile

62.5%